By George Norman - Software News Editor
Added on 06 Jul 2009(608 Views)
Security expert Charlie Miller, which you might remember from the PWN2OWN competition where he managed to hack into Apple’s Safari in about 10 seconds, has uncovered a rather nasty security vulnerability affecting the iPhone. The vulnerability that Charlie Miller uncovered refers to the manner in which the iPhone handles text messages (SMS), which in turn could grant a person with malicious intent to gain root access to the device.

Unfortunately for those of you that want more details on the matter, Charlie Miller could not provide in-depth details on the vulnerability he uncovered, for obvious security reasons. If the details were to be released before Apple has time to work on a fix then anyone could potentially exploit this SMS vulnerability.


What we do know is this: the iPhone handles SMS messages in a dangerous manner that could allow a person with malicious intent to remotely install and run unsigned software code with root access on the device. The attacker could for example send software code on the iPhone via SMS and thanks to this malicious code the attacker could turn on the device’s microphone and listen in to your conversation, could turn on the device’s GPS and know precisely where you are, or could add the iPhone to a botnet or distributed denial of service attack.

It sounds gloom, I know, but there is one upside. Charlie Miller does not have an exploit for this vulnerability so far, just a very suspicious crash (he can crash part of the device and temporarily disconnect it from the network). On top of that Apple is reportedly already aware of this issue and is currently working with Miller on a patch. The fix is supposed to be rolled out later this month, before Charlie Miller is due to make a detailed presentation on how to “inject SMS messages into iPhone, Android, and Windows Mobile devices” at the Black Hat 2009 event (25th through 30th of July, Caesar’s Palace, Las Vegas).

In related news, we already know that Apple is working on the iPhone OS 3.1 update. Let’s just hope that alongside the fixes and improvements it has to offer, a fix for this SMS vulnerability is also included.





Don't forget to:

RSS


Tags: Apple, iPhone, SMS, Vulnerability, Charlie Miller

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools

Top Downloads